{"id":13665,"date":"2024-05-21T10:08:34","date_gmt":"2024-05-21T07:08:34","guid":{"rendered":"https:\/\/forklog.com\/en\/gala-games-exploit-results-in-over-200-million-loss\/"},"modified":"2024-05-21T10:08:34","modified_gmt":"2024-05-21T07:08:34","slug":"gala-games-exploit-results-in-over-200-million-loss","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/gala-games-exploit-results-in-over-200-million-loss\/","title":{"rendered":"Gala Games Exploit Results in Over $200 Million Loss"},"content":{"rendered":"<p>An unknown actor minted and withdrew 5 billion GALA tokens from the Web3 gaming platform Gala Games, amounting to approximately $210 million, according to <a href=\"https:\/\/etherscan.io\/tx\/0xa6d90abe17d17743a9cecab84bcefb0fd0bbfa0c61bba60fd2f680b0a2f077fe\">Etherscan<\/a> data.<\/p>\n<div class=\"wp-block-text-wrappers-update-2 article_update\"><time class=\"gtb_text-wrappers_update_time\">22 May 2024 | 14:54<\/time><span class=\"gtb_text-wrappers_update_head\">Update: <\/span><\/p>\n<p>The hacker who breached Gala Games <a href=\"https:\/\/etherscan.io\/tx\/0x273c6b54fea8b0d616fb3270698dd4387ec3fefc7b0e290330b4019c35a984b1\">returned<\/a> ~5913 ETH (approximately $22.1 million at the time of the transaction) to the project, proceeds from the sale of 600 million stolen GALA.<\/p>\n<p>The team converted the cryptocurrency back into native tokens.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">Update: The funds from the recent security incident have been recovered.<\/p>\n<p>At this time we will be using <a href=\"https:\/\/twitter.com\/hashtag\/GalaSwap?src=hash&#038;ref_src=twsrc%5Etfw\">#GalaSwap<\/a> to convert the Ethereum back to <a href=\"https:\/\/twitter.com\/search?q=%24GALA&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$GALA<\/a>.<\/p>\n<p>\u2014 Gala Games (@GoGalaGames) <a href=\"https:\/\/twitter.com\/GoGalaGames\/status\/1793067133129113928?ref_src=twsrc%5Etfw\">May 21, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The developers also <a href=\"https:\/\/x.com\/GoGalaGames\/status\/1793082973320859946\">initiated a vote<\/a> among nodes on a governance proposal concerning the deployment of a temporary contract to &#8220;formalize the burning&#8221; of the unauthorized 5 billion GALA tokens.<\/p>\n<\/div>\n<p>The perpetrator managed to sell 600 million GALA through the decentralized exchange Uniswap. Consequently, the asset&#8217;s price plummeted by about 20% in less than an hour\u2014from approximately $0.048 to $0.038 (<a href=\"https:\/\/www.coingecko.com\/en\/coins\/gala\">CoinGecko<\/a>).<\/p>\n<p>At the time of writing, the price has partially recovered, with a daily decline of just over 3%.<\/p>\n<p>The exploit was confirmed by Gala Games co-founder Eric Schiermeyer. He stated that the team identified the smart contract compromise within 45 minutes and terminated unauthorized access. The remaining 4.4 billion GALA held by the hacker were locked and burned.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">Hey Everyone\u2026<\/p>\n<p>I always knew there was a reason I never talk shit about other projects getting hacked\u2026I&#8217;m sorry to say we had an incident that resulted in the unauthorized SALE of 600million (21million usd) <a href=\"https:\/\/twitter.com\/search?q=%24GALA&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$GALA<\/a> tokens and the effective BURN of 4.4 billion tokens.<\/p>\n<p>We\u2026<\/p>\n<p>\u2014 benefactor (@Benefactor0101) <a href=\"https:\/\/twitter.com\/Benefactor0101\/status\/1792698768166715776?ref_src=twsrc%5Etfw\">May 20, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>&#8220;We breached our internal control system\u2026 This should not have happened, and we are taking measures to ensure it never happens again. We believe we have identified the perpetrator and are currently working with the <span data-descr=\"Federal Bureau of Investigation\" class=\"old_tooltip\">FBI<\/span>, the Department of Justice, and a network of international agencies,&#8221; he stated.<\/p>\n<\/blockquote>\n<p>The Gala Games team described the incident as isolated, with the cause addressed. Developers promised to disclose additional information as the investigation continues.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">The security incident involving the <a href=\"https:\/\/twitter.com\/search?q=%24GALA&#038;src=ctag&#038;ref_src=twsrc%5Etfw\">$GALA<\/a> token has been contained and the impacted wallet has been frozen.<\/p>\n<p>This was an isolated incident, the cause of which has been addressed and we are working closely with law enforcement to investigate the individuals behind the breach.\u2026<\/p>\n<p>\u2014 Gala Games (@GoGalaGames) <a href=\"https:\/\/twitter.com\/GoGalaGames\/status\/1792727587460104377?ref_src=twsrc%5Etfw\">May 21, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Back in 2023, project co-founders Schiermeyer and Wright Thurston accused each other of stealing $130 million.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An unknown actor minted and withdrew 5 billion GALA tokens from the Web3 gaming platform Gala Games, amounting to approximately $210 million, according to Etherscan data. 22 May 2024 | 14:54Update: The hacker who breached Gala Games returned ~5913 ETH (approximately $22.1 million at the time of the transaction) to the project, proceeds from the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":13664,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,44,1155],"class_list":["post-13665","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-cybercrime","tag-games-and-gamefi"],"aioseo_notices":[],"amp_enabled":true,"views":"43","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/13665","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=13665"}],"version-history":[{"count":0,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/13665\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/13664"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=13665"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=13665"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=13665"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}